CVE-2026-35054 PUBLISHED

XenForo Stored Cross-Site Scripting via BB Code Rendering

Assigner: VulnCheck
Reserved: 01.04.2026 Published: 01.04.2026 Updated: 01.04.2026

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor XenForo
Product XenForo
Versions
  • affected from 2.3.0 to 2.3.9 (excl.)

Credits

  • Antisocial finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE